Skip to content

Security

Security and your data

What protects your filings, your DSC and your customers’ details — said plainly, and no further than the privacy policy and the data processing agreement already commit us to.

Your DSC stays yours

  • Your private key never leaves your token. The token signs, and asks for its PIN, exactly as it does on ICEGATE’s own portal. We never hold, copy or ask for your DSC.
  • The desktop signer is given only a fingerprint of your filing — never the consignee, the BL or anything else on it — and signs for this site and nothing else. It is published under TAGQA Pty Ltd’s code-signing certificate; what it does and does not do.
  • Before anything reaches customs, the signature is checked against the exact bytes you reviewed, so a stray change between freezing and signing cannot become a filing you did not see.
  • If your IT department will not allow the signer, sign on ICEGATE’s own portal instead and bring the signed file back.

Your organisation is walled off

  • One organisation can never read another’s filings. The separation is enforced by the database itself, not only by our application.
  • Sign-in sessions live in the database, so access ends the moment a member is removed or their role changes — on the web and on the phone alike.
  • Everyone can see where their account is signed in and sign any other device out themselves, and is e-mailed when their account signs in on a device it has not been used on before.
  • Your Org Admin can restrict the whole organisation to your office’s IP addresses, and set how long your uploaded files are kept.

Where your data is kept

Your filings, our database and the files you upload are kept in Mumbai. A few supporting services — the assistant, the AI models that read bills you e-mail us, e-mail and our logs — run outside India; the data processing agreement lists each one and where it runs.

Files you upload

  • Every file uploaded to SCMTR is kept — CSNs, ACK files, shipping line filings and customs’ replies — in a private storage bucket in Mumbai, for two years after we last receive it, or as long as a filing here still relies on it. Your organisation can set its own period.
  • That includes a file you check for free without signing in. It is kept without your name, and nothing in it is sent to ICEGATE.
  • You can ask for any file to be deleted, and it will be.

What we never do

  • Sell your data, advertise with it, or use your filings or files to train AI models.
  • Send anything to ICEGATE that you have not signed.
  • Send the same file to customs twice by mistake: a file already sent and unanswered, or already accepted, is stopped and the earlier upload named — it goes again only if someone confirms it with a reason, and that is recorded.
  • API keys are stored so that even we cannot read them back, and other credentials are stored encrypted.
  • Every webhook is signed, so your systems can tell a message really came from SCMTR.io.
  • Links you share — a read-only filing, a CSN reference card for the shipping line, a case — are unguessable, expire, and can be withdrawn. An unknown, withdrawn or expired link gets the same “unavailable” page, so a guess learns nothing.

The site itself

  • Everything is encrypted in transit and at rest, and no page of ours can be embedded inside another site.
  • A published security contact for researchers: security.txt.

If something goes wrong

  • If a breach affects your data, your Org Admins are told without undue delay and in any case within 72 hours of it being confirmed, with what happened and what is being done.
  • Report a security problem to support@scmtr.io with “Security” in the subject.
  • Privacy requests and grievances under India’s Digital Personal Data Protection Act go to our Grievance Officer — how, in the privacy policy.

What we do not claim

  • SCMTR.io holds no ISO 27001 or SOC 2 certification. What we commit to is in writing in the data processing agreement, and we answer a reasonable security questionnaire once a year.
  • SCMTR.io is independent — not affiliated with ICEGATE, CBIC or Indian Customs.
  • A clean check is not a promise that customs will accept a filing.